Privacy Policy (pursuant to EU Regulation 2016/679)
Dear Customer,
Pursuant to current legislation on the protection of personal data (EU Regulation 2016/679 and Legislative Decree 196/2003, as amended and supplemented by Legislative Decree 101/2018), we wish to inform you that your personal data will be processed fairly and transparently, for lawful purposes, and in a manner that protects your privacy and your rights. In compliance with the provisions of Article 13 of EU Regulation 2016/679, we inform you that:
1. Data controller
Data controller Name GEINGROS di Carevaggini Enrico Antonio & C. SAS
N. Vat 00917650491
Registr. office Corso Italia 44 57027 San Vincenzo (LI)
E-mail [email protected]
PEC [email protected]
Web site 1 https://www.residencevillapiani.it/
Web site 2 https://www.residencevillalivia.it/
2. Treatment methods
Processing is carried out both using electronic tools that guarantee high levels of security and confidentiality, and with the aid of paper-based means, appropriate for carrying out the services offered, in compliance with the security and protection measures imposed by industry regulations.
3. Nature of the data processed
The data processed includes your personal details, contact information (telephone number, email, etc.), and data relating to the request and purchase of services and products (subject of the contract, terms, conditions, duration, etc.).
If you make special requests due to personal health conditions, disabilities, or any food intolerances, allergies, or other medical conditions affecting you or a companion, the processing may also include such information, which falls within the category of sensitive data pursuant to Article 9 of EU Regulation 2016/679. In all these situations, such data is processed verbally only, is communicated exclusively to the relevant personnel, and is always deleted at the end of each stay.
4. Purpose of the processing and their legal basis
This data processing activity is aimed at managing customer relationships and is structured into the following activities, aimed at ensuring the best possible customer service, in compliance with applicable laws. The various procedures adopted by the data controller for customer management are described below, each indicating the respective lawfulness criteria:
4.a. Management of requests and estimates
Requests for information and quotes can be made by phone, by email by filling out the contact form on the company websites on the 'Contacts' page, or via the WhatsApp Business app, or by clicking the appropriate icon on the website's home page.
4.b. Booking Management
Reservations can be made by phone, email, through the WhatsApp Business app, through the two company websites, through a booking engine, or through an OTA (such as Booking.com and Airbnb). Website reservations can be made either through the Kross Booking software or through the dedicated contact form.
4.b.1. Booking through KROSS BOOKING
On both company websites, the Kross Booking software for the website www.residencevillapiani.it can be accessed through the "BOOKING ONLINE" page by clicking the "BOOK NOW" button; for the website www.residencevillalivia.it, it is accessed directly on the homepage. Upon completion, the user is asked to check the acceptance box for the contractual terms and conditions and to declare that they have read the privacy policy.
Once the submission is complete, the user receives a confirmation email informing them that the procedure must still be completed as required at the next visit. Section 4.b.7.
4.b.2. Booking via contact form
As an alternative to booking via the online booking software, users can book by completing the contact form on the "Contacts" page. At the bottom of this form, there are two acceptance boxes: the first must be checked to proceed, as it indicates acceptance of the terms and conditions of the contract and acknowledgement of the privacy policy, with separate links to the relevant pages; the second is a box for consenting to the processing of personal data provided for advertising and marketing purposes. A summary notice is located next to this box, with a link to the full privacy policy. Booking requests submitted via the contact form will be sent to the Property via email.
4.b.3. Booking by email
The user can make a reservation by sending a request via the email address indicated on the websites.
In the cases referred to in Points 2 and 3 (requests via the contact form or directly by email), the data controller will respond by email, alternatively, at its discretion, using a quote template in a Word document prepared by the data controller, or by processing the quote using the Kross Booking management system. In the latter case, the user's data will be entered into the management system solely for the purpose of processing the quote and will be deleted if the quote is not followed by a booking, unless the data subject has given consent to processing for marketing and advertising purposes.
4.b.4. Booking via WHATSAPP
Bookings can also be made via WhatsApp Business by clicking the appropriate icon on the website homepage. The data controller responds to customer requests via WhatsApp, but to complete the booking, the user always requires an email address to which the Booking Contract can be sent.
From this point onwards, the same procedure described in Section 4.b.7 below applies.
4.b.5. Booking by phone
If the interested party contacts the Facility by telephone to request information and decides to book by this means, he or she will be asked to indicate an email account where the Booking Contract will be sent to initiate the booking procedure, as described in the following Point 4.b.7.
4.b.6. Reservation in person at the facilities
In the case of direct bookings at the Front Office of one of the two Facilities, the Customer is asked to provide an email account to which the documentation necessary to complete the booking procedure will be sent, as per Point 4.b.7 below.
4.b.7. Completing the booking process
All reservations, regardless of the contact method, are initiated by sending the Booking Contract to the email address provided and are completed through manual intervention by the designated staff, who access the Kross Booking management system and change the booking status once the Accommodation has received proof of payment of the agreed-upon amount. Following this status change in the management system, a confirmation email is sent and, at least one week before the scheduled arrival at the Accommodation, an online check-in email is sent.
4.b.8. Possible processing of special data pursuant to art. 9 of EU Regulation 2016/679
When booking or upon arrival, guests may have specific requests due to their personal health conditions or disabilities. The data and information provided will be handled verbally only, with the utmost confidentiality, and exclusively by the relevant staff.
4.c. Customer Management Accommodation Facility
The processing concerns the personal data of guests acquired by the accommodation provider during the booking process for the reception and management of their stay, including the provision of additional services offered by the facility; payment management, including through the use of third-party banking/financial entities; and compliance with public-administrative, accounting, and tax legal obligations.
The guest's stay is managed through the Kross Booking management system, which also includes consent for processing for marketing purposes.
4.c.1. Special requests for health reasons or in the presence of a disability
When booking or upon arrival, you may have specific requests due to your or a companion's personal health conditions or disabilities. In both cases, the data and information provided will be communicated verbally only to the relevant staff and will be treated with the utmost confidentiality and exclusively to meet the customer's needs.
4.c.2. Security deposit or credit card details as a guarantee
Upon your first entry to the property, you will be asked to leave a security deposit in cash or provide your credit card details. This will ensure that the data controller is not liable for any damage caused to the assigned rooms and/or furnishings during your stay by you and/or any accompanying persons.
Upon your departure, as soon as the data controller has verified the condition of the rooms you stayed in, your credit card details will either:
a) be immediately deleted if no damage has occurred;
b) be used, in accordance with the agreed-upon terms, to cover the cost of repairing any damage to the rooms and/or furnishings.
4.c.3. Additional service for sending welcome emails aimed at facilitating the customer's stay
From the time of customer registration and for the entire duration of the stay, the Kross Booking management system generates several emails with the exclusive purpose of facilitating the customer's stay.
4.c.4. Additional service for access to the Limited Traffic Zone
During the summer months, customers needing to reach the two facilities are required to provide their vehicle's license plate to be communicated to the Local Police for management of access to the Limited Traffic Zone. Failure to provide this information will prevent access to the offered service.
4.d. Management of customer registration on the Guest Portal
This processing is intended to comply with the legal obligation to verify the identity of guests and the related fulfillment of the obligation under the Consolidated Law on Public Security (Article 109 of Royal Decree No. 773 of June 18, 1931, TULPS) to upload the personal details of guests staying at the accommodation facility to the Guest Portal set up by the State Police, for public security purposes, in accordance with the procedures established by the Ministry of the Interior with the Decree of January 7, 2013, as amended by the Decree of September 16, 2021. The Decree of September 16, 2021, in particular, while confirming the maximum twenty-four-hour deadline for entering guest details, reduces this deadline to six hours for stays of less than twenty-four hours.
Providing data is mandatory in compliance with a regulatory provision and therefore does not require the customer's consent (Article 6, paragraph 1, letter c) of EU Regulation 2016/679).
The company's procedure requires the necessary personal data to be uploaded to the Kross Booking management system. The management system is programmed to automatically fill out the forms, while subsequent submissions are done manually, again through the booking management system.
Staff typically complete the management system upon guests' arrival and immediately return their identification documents. However, guests may send a photo of their identification documents via email or WhatsApp, or provide consent for a photocopy or photograph of their identification document to be taken using a company smartphone. In all cases, the image is used by staff only to fulfill the obligation to send guest data to the Guest Portal as soon as possible, and in any case within the legal deadlines. Once this has been completed, the copy will be permanently destroyed.
4.e. Issuing a Receipt or Invoice
For tax purposes, the Company always issues invoices: you are required to provide us with your personal data required to prepare the document, which, once issued, will be subject to the retention periods established by law. The data is processed by us and our representatives and is disclosed externally only in compliance with legal obligations. If you refuse to provide the data required for the above-mentioned obligations, we will not be able to provide you with the requested service.
For these purposes, processing is carried out without the need to obtain your consent (Article 6, paragraph 1, letter c) of EU Regulation 2016/679), as this is required by law.
4.f. Legitimate interest of the data controller or third parties
In some cases, processing may be necessary to pursue the legitimate interests of the data controller or third parties, provided that your interests or fundamental rights and freedoms do not prevail:
in such cases it is not necessary to obtain your consent pursuant to art. 6, paragraph 1, letter f) of EU Regulation 2016/679.
4.g. Speed up the registration process for your future stays at our facility
For this purpose, after obtaining your consent pursuant of art. 6 par. 1 lett. a) and art. 7 GDPR, Revoke your consent at any time. Your personal data will be used when you return to our house for the purposes set out in the previous sections and will be retained for a period no longer than necessary to achieve the purposes for which it was collected. You may withdraw your consent at any time and exercise your rights as further specified in Section 11.
4.h. Sending newsletters and advertising material (Mailing list service)
The processing involves maintaining and using a contact list (email addresses provided during website registration and/or booking, or during your stay at the accommodation) for marketing purposes and to send newsletters containing advertising material regarding promotions, rate updates, or offers. This processing can only be carried out with your express and specific consent, which can be revoked at any time.
The data controller prepares the contact list and sends it to the website operator, who is responsible for sending the newsletters.
5. Duration of treatment
The processing lasts for the duration of the validity and effectiveness of the contract between the parties, and beyond, if further processing is carried out to pursue the data controller's overriding interest or to fulfill a legal obligation. In these latter cases, the data controller, in accordance with the principles set forth in Article 5 of EU Regulation 2016/679, undertakes to delete the data as soon as the purposes for which they were collected have been fully achieved.
Duration of processing based on the data subject's consent
In the case of processing based on the data subject's consent, you may withdraw your consent at any time pursuant to Art. 7 GDPR and you may exercise the other rights set forth in Articles 15–22 GDPR, as further specified in Section 11 of this policy. In any case, the duration of processing may not exceed the purpose for which the data was collected.
Duration of processing in the event that the request for information or a quote is not followed by the booking and stay of the interested party
In all cases where the request for information and/or a quote is not followed by a booking, your personal data provided for such services will be deleted after a period of 7 days, within which it is reasonable to assume that you can calmly consider the information and/or quote received and decide whether to accept the offer or request additional accommodation options. After this period, your personal data will be permanently deleted from all databases, except where you have expressly consented to the processing of your personal data for advertising and marketing purposes.
Duration of processing in the event that the interested party completes the booking and stays at our facilities
The Kross Booking management system is cloud-based, and the data stored therein is subject to the supplier's privacy policies.
When the invoice is issued, your personal data, required for its compilation, is entered into the dedicated software and retained for the following 10 years as required by law, and even longer in the event of a pending tax audit. Electronic invoices are sent to the Exchange System (SDI) managed by the Revenue Agency within the legal deadlines.
Whatsapp chats are completely deleted within 30 days of departure.
6. Data voluntarily provided by the interested party
If you choose to pay using one of the available payment methods (bank transfer, credit card, debit card, etc.), in addition to the data required for the provision of the services referred to in point 3, you will be required to provide us with all the data necessary to complete these procedures. Failure to provide even some of these data will make it impossible to provide the service.
The express and voluntary submission of data by completing the contact forms and/or sending emails to the addresses listed on our website entails our subsequent acquisition of the same data. All requested data (generally, name and surname, telephone number, and email address) are necessary for us to respond to your requests and/or fulfill the service you request. Specific summary information is provided and/or displayed on the individual pages of the website dedicated to the provision of specific services upon request.
Failure to provide consent to the use of your personal data for the performance of one or more ancillary services does not in any way prevent or exclude the main service.
7. Obligation or option to provide data and consequences of any refusal
The personal data requested from time to time is necessary for us to be able to carry out the services offered: failure to provide them, in whole or in part, consequently makes it impossible to carry out the services themselves.
8. Communication and dissemination of collected data
The data collected for the purposes and services referred to in Section 4 are not "disseminated" by us; in other words, they are not disclosed to unspecified parties in any way, including by making them available or consulting them. However, they may be "communicated" by us, meaning they are disclosed to one or more specific parties, specifically:
- parties who can access the data in compliance with a legal obligation, within the limits established by the law itself;
- credit and/or financial institutions, if payment by electronic means is required;
- our consultants and collaborators for the ordinary management of business activities and for the fulfillment of obligations related to the services described above;
- government administrations and other public bodies subject to disclosure obligations.
9. Data transfers to non-EU countries
Your personal data collected for the purposes and services referred to in point 4 will under no circumstances be transferred to countries outside the EU.
10. Profiling
Your personal data collected for the purposes and services referred to in point 4 will under no circumstances be subject to profiling or other automated processing pursuant to art. 22 of EU Regulation 2016/679.
11. The rights of the interested party (articles 13/22 and 77/79 of EU Regulation 2016/679)
If, as a data subject, you wish to exercise the rights set forth in Articles 13/22 and 77/79 of EU Regulation 2016/679 in relation to your personal data, or if you have other questions or requests regarding this Policy, you can contact the Data Controller using the contact details provided in Section 1 of this Policy.
The Data Controller is available to respond to your requests.
We also inform you that the law grants you certain rights with respect to the data processed by the Data Controller.
Specifically, as a data subject, pursuant to Article 4, No. 1) of EU Regulation 2016/679, you have the right to:
- withdraw consent at any time. The data subject may always withdraw previously given consent to the processing of their personal data (Article 13, paragraph 2, letter c) of EU Regulation 2016/679);
- object to the processing of their data. The data subject may object to the processing of their data in the cases set forth in Article 21 of EU Regulation 2016/679;
- access their data. The data subject has the right to obtain information on the data processed by the Data Controller, on certain aspects of the processing, and to receive a copy of the data processed (Article 15 of EU Regulation 2016/679);
- verify and request rectification. The data subject may verify the accuracy of their data and request its updating or correction (Article 16 of EU Regulation 2016/679);
- Obtain restriction of processing. When certain conditions are met, the data subject may request restriction of processing. In this case, we will not process the data for any purpose other than its storage (Article 18 of EU Regulation 2016/679);
- Obtain the deletion or removal of their personal data. When certain conditions are met, the data subject may request the Data Controller to delete their data (Article 17 of EU Regulation 2016/679). In these cases, we will certainly delete the data as quickly as possible;
- Receive their data or have it transferred to another controller (data portability). The data subject has the right to receive his or her data in a structured, commonly used, and machine-readable format and, where technically feasible, to have that data transmitted to another controller without hindrance. This provision applies when the data is processed by automated means and the processing is based on the data subject's consent, on a contract to which the data subject is party, or on contractual obligations related to it (Article 20 of EU Regulation 2016/679);
- not to be subject to a decision based solely on automated processing, including profiling, where the exercise of this right is permitted (Article 22 of EU Regulation 2016/679);
- lodge a complaint. The data subject may lodge a complaint with the competent data protection supervisory authority (Article 77 of EU Regulation 2016/679);
- take legal action (Article 79 of EU Regulation 2016/679).
https://www.residencevillapiani.it/Informativa-Privacy-esp-ENG.pdf